HDPrint legal

Security Overview

The security boundaries currently used by the HDPrint application.

Version 1.0 · Effective 2026-08-27

Application boundaries

Server routes validate input, use authenticated sessions where required, and keep the Supabase service-role key server-side. Database access is designed around row-level security. Uploaded files are stored through the configured storage integration and should be accessed only through authorized order relationships.

Limitations

Cloudinary, Supabase, payment, email, malware scanning, backups, monitoring, and deployment hardening remain configuration-dependent. This page is an engineering overview, not a guarantee of encryption, availability, certification, or a particular data residency.

Report an issue

Report suspected security issues privately to hello@example.com. Do not include secrets or document contents.